EU AI Act Hub

EU AI Act Compliance Hub: Risk Tiers, Obligations, Evidence

Figure out what applies to you. Generate checklists and audit-ready artifacts you can forward to auditors, counsel, and your board.

Orientation only. Not legal advice.

Showing guidance forNot sure · Chatbot
Timeline

What changed and when

Key dates in plain language, with a clear last-updated date. The Digital Omnibus on AI, adopted 29 June 2026, moved the Annex III high-risk obligations and the FRIA requirement from 2 August 2026 to 2 December 2027, and Annex I product-embedded high-risk AI to 2 August 2028. The Article 50 transparency duties still apply from 2 August 2026.

Last updated: Jul 27, 2026
Jul 12, 2024
Published in the Official Journal
Start of the countdown. Use this date to sanity-check phased applicability timelines.
Aug 1, 2024
Entered into force
The regulation is in force, with many obligations phasing in later.
Feb 2, 2025
Prohibited practices apply (Article 5)
High-risk or not, banned use cases should be removed or redesigned.
Aug 2, 2025
General-purpose AI (GPAI) obligations begin
Provider-side duties start phasing in for GPAI models and systemic-risk models.
Aug 2, 2026
Article 50 transparency duties apply
Disclosure and AI-content marking for every system that talks to a person or produces synthetic content.
Aug 2, 2027
AI regulatory sandboxes operational
Each member state runs at least one sandbox under Article 57.
Dec 2, 2027
High-risk obligations apply (Annex III)
Moved from 2 August 2026 by the Digital Omnibus on AI. The Article 27 FRIA and Article 49 registration follow this date.
Aug 2, 2028
High-risk AI in regulated products (Annex I)
Moved from 2 August 2027. Aligns with the sectoral conformity assessment the product already needs.
Resource library

Compliance library

Pillar links that map obligations to concrete artifacts, guides, and tools.

Risk classification

Determine whether your system is prohibited, high-risk, or limited risk.

Requirements + documentation

Translate articles into technical documentation and audit-ready artifacts.

Stakeholder guides

Provider, deployer, and GPAI obligations explained in plain language.

Implementation + evidence

Build the operational evidence trail that regulators and auditors expect.

Industry-specific guides

Tailored compliance roadmaps for regulated verticals.

Unacceptable · High-risk · Limited · Minimal

Risk tiers (operational view)

The essentials for each tier

Unacceptable

Unacceptable (prohibited)

Stop-ship risks. Remove or redesign and keep remediation evidence.

Typical examples

  • Prohibited practices (Article 5)
  • Certain biometric or manipulative use patterns

What you need to have

  • A “fail-closed” policy gate (blocks prohibited paths)
  • A remediation decision trail (tickets, approvals, releases)
  • Evidence of removal/redesign and regression tests
High-risk

High-risk (Annex III)

Operationalize controls and build an audit-ready evidence package.

Typical examples

  • Hiring/HR decision support
  • Credit/insurance decisions
  • Sensitive biometrics
  • Healthcare ops

What you need to have

  • Risk management + verification evidence
  • Annex IV-aligned technical documentation
  • Logging/traceability and human oversight records
  • Quality processes (QMS) + monitoring cadence
Limited

Limited risk (transparency)

Add disclosures and retain evidence that you did.

Typical examples

  • Chatbots and conversational agents
  • AI-generated or manipulated content

What you need to have

  • User disclosures in the flow
  • Proof of disclosure (screenshots + telemetry events)
  • Change control for model/policy updates
Minimal

Minimal risk

Baseline governance so you can prove what ran and why.

Typical examples

  • Internal tools and low-stakes automation (often)

What you need to have

  • System card + lightweight risk review
  • Basic logging (what ran when) and retention
  • Monitoring + incident handling path
3 minutes

Check your EU AI Act obligations

Answer up to ten questions. Get an indicative classification, the obligations to review, and the evidence to keep. Confirm the result with your legal or risk team.

Checker
Question 1 of 9

Your role

Which best describes you?

Provider places a system on the market; deployer uses it in operations.

Directory

Popular deep dives

Our most-read detailed guides: step-by-step actions and evidence checklists.

Annex III high-risk list (with examples)

Providers & deployers mapping use cases to high-risk categories

A practical “does this look like Annex III?” checklist and evidence pointers.

7 minRead

Article 5 prohibited AI practices (operational checklist)

Anyone shipping AI features into the EU market

A fast filter for “stop-ship” risks and how to document remediation.

6 minRead

Article 50 transparency obligations (plain language)

Chatbots, conversational agents, deepfakes, and content generation teams

What disclosures to add, and what evidence to keep that you did.

7 minRead

GPAI + foundation model obligations (orientation)

Teams building on, providing, or deploying general-purpose AI models

Provider vs deployer obligations and what to request from vendors.

8 minRead

Conformity assessment explained

High-risk teams preparing for audits and go-live

What “assessment” means operationally and what artifacts to assemble.

7 minRead

Technical documentation checklist (Annex IV-aligned)

Engineering and compliance teams drafting documentation packages

A skeleton you can use to build a defensible dossier.

9 minRead

Quality management system (QMS) essentials

Providers operationalizing repeatable compliance

Minimum viable QMS processes and evidence to retain.

8 minRead

Fines and penalties (plain-English)

Executives and risk owners budgeting compliance work

A non-alarmist view of enforcement signals and how to reduce exposure.

6 minRead
Free download

Templates + artifacts

Forwardable outputs that unlock internal buy-in.

Compliance Starter Pack

  • AI System Card template
  • Risk assessment outline (risk register style)
  • Human oversight plan checklist
  • Technical documentation skeleton
  • Vendor due diligence checklist (deployer-focused)
  • Logging/audit event checklist (evidence-ready)

Need the full Annex IV structure? Grab the Annex IV template pack.

Fictional samples. Not legal advice.

Need an evidence path?

KLA turns obligations into controls, controls into assurance, and assurance into defensible evidence you can export.

Control plane

Operationalize compliance

From obligations → controls. From controls → assurance. From assurance → defensible evidence.

Govern

Policy-as-code checkpoints pause risky steps for human review, enforce disclosures, and block prohibited paths.

  • Checkpoints + escalation rules
  • Change control tied to releases
  • Exception approvals with expiry

Assure

Sampling checks accuracy/grounding, tracks near-misses, and makes drift visible.

  • Sampling evaluations + thresholds
  • Near-miss and violation trends
  • Alerting + escalation evidence

Prove

Tamper-evident, append-only audit trail with Evidence Room exports you can hand to auditors.

  • Tamper-evident audit trail
  • Evidence Room export bundles
  • Integrity proofs for defensibility
Not legal advice

FAQ

Fast answers to common scope and implementation questions.

Next step

Ready to turn confusion into evidence?

Run the checker, download templates, or book a short readiness call.

EU AI Act Compliance Guide 2026 | Risk Assessment & Checklist